CVE-2026-55088: CWE-200: Exposure of Sensitive Information to an Unauthorized Actor in ether etherpad
Etherpad versions from 2.6.0 up to but not including 3.1.0 contain a vulnerability in the token transfer mechanism. The POST /tokenTransfer endpoint stores author tokens without expiration or removal after use, and the GET /tokenTransfer/{uuid} endpoint exposes these tokens. An unauthenticated attacker with a valid transfer UUID can repeatedly redeem it to obtain fresh author cookies and impersonate the author for pad read and write operations. This issue is fixed in version 3.1.0.
AI Analysis
Technical Summary
Etherpad's token transfer feature in versions >=2.6.0 and <3.1.0 uses a POST /tokenTransfer endpoint to store author tokens and a GET /tokenTransfer/{uuid} endpoint to retrieve them. The tokens have no expiration and are not deleted after redemption, allowing an attacker who obtains a transfer UUID to repeatedly redeem it and receive fresh author cookies. This enables unauthorized access to pad content with read and write privileges. The vulnerability is identified as CWE-200 (Exposure of Sensitive Information) and CWE-294 (Authentication Bypass). The flaw is fixed in version 3.1.0.
Potential Impact
An unauthenticated attacker who obtains a valid transfer UUID can repeatedly redeem it to obtain fresh author tokens and cookies, allowing them to impersonate the originating author. This grants unauthorized read and write access to Etherpad collaborative documents, potentially exposing sensitive information and enabling unauthorized modifications.
Mitigation Recommendations
Upgrade Etherpad to version 3.1.0 or later, where this vulnerability is fixed. The fix addresses the lack of expiration and removal of tokens after redemption. No other mitigation is indicated by the vendor advisory.
CVE-2026-55088: CWE-200: Exposure of Sensitive Information to an Unauthorized Actor in ether etherpad
Description
Etherpad versions from 2.6.0 up to but not including 3.1.0 contain a vulnerability in the token transfer mechanism. The POST /tokenTransfer endpoint stores author tokens without expiration or removal after use, and the GET /tokenTransfer/{uuid} endpoint exposes these tokens. An unauthenticated attacker with a valid transfer UUID can repeatedly redeem it to obtain fresh author cookies and impersonate the author for pad read and write operations. This issue is fixed in version 3.1.0.
CVSS v3.1
Score 6.8medium
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Etherpad's token transfer feature in versions >=2.6.0 and <3.1.0 uses a POST /tokenTransfer endpoint to store author tokens and a GET /tokenTransfer/{uuid} endpoint to retrieve them. The tokens have no expiration and are not deleted after redemption, allowing an attacker who obtains a transfer UUID to repeatedly redeem it and receive fresh author cookies. This enables unauthorized access to pad content with read and write privileges. The vulnerability is identified as CWE-200 (Exposure of Sensitive Information) and CWE-294 (Authentication Bypass). The flaw is fixed in version 3.1.0.
Potential Impact
An unauthenticated attacker who obtains a valid transfer UUID can repeatedly redeem it to obtain fresh author tokens and cookies, allowing them to impersonate the originating author. This grants unauthorized read and write access to Etherpad collaborative documents, potentially exposing sensitive information and enabling unauthorized modifications.
Mitigation Recommendations
Upgrade Etherpad to version 3.1.0 or later, where this vulnerability is fixed. The fix addresses the lack of expiration and removal of tokens after redemption. No other mitigation is indicated by the vendor advisory.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-vqfp-p66c-xrp9
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-55088"]
- Ecosystems
- ["npm"]
- Database Specific Severity
- MODERATE
- Cvss Version
- 3.1
Threat ID: 6a7e0370bf8831d5398f957e
Added to database: 08/13/2026, 17:48:32 UTC
Last enriched: 09/13/2026, 13:02:24 UTC
Last updated: 09/28/2026, 09:57:42 UTC
Views: 76
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.